Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 22 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences its nbFile, files, and sessionFilePathName members without checking for null. A process running at the same or a higher Windows integrity level on the same desktop can send NPPM_SAVESESSION with a null lParam, immediately terminating Notepad++ and causing denial of service and loss of unsaved documents. This issue is fixed in version 8.9.8. | |
| Title | Notepad++: Null pointer dereference in NPPM_SAVESESSION message handler causes crash (DoS) | |
| Weaknesses | CWE-476 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T17:40:34.136Z
Reserved: 2026-09-04T19:29:21.059Z
Link: CVE-2026-86056
Updated: 2026-09-22T17:40:26.332Z
Status : Received
Published: 2026-09-22T18:17:24.087
Modified: 2026-09-22T18:17:24.087
Link: CVE-2026-86056
No data.
OpenCVE Enrichment
Updated: 2026-09-22T18:45:18Z